US2025254190A1PendingUtilityA1

Investigation of threats using queryable records of behavior

Assignee: ABNORMAL AL INCPriority: Mar 12, 2020Filed: Jan 13, 2025Published: Aug 7, 2025
Est. expiryMar 12, 2040(~13.6 yrs left)· nominal 20-yr term from priority
H04L 63/1425H04L 67/125H04L 63/1433H04L 67/30
69
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Data of a digital communication account of a first user are parsed for one or more attributes of a series of digital activities including a first digital activity initially scored as non-malicious. Based on the parsed data, a searchable user communication digital profile is generated for the first user. The searchable user communication digital profile is searched based on a second digital activity and receiving a search result associated with the first digital activity. The first digital activity is rescored as malicious based on the search result. A security action associated with the rescored first digital activity is performed.

Claims

exact text as granted — not AI-modified
1 . A system method comprising:
 parsing data of a digital communication account of a first user for one or more attributes of a series of digital activities including a first digital activity initially scored as non-malicious;   based on the parsed data, generating a searchable user communication digital profile for the first user;   
       searching the searchable user communication digital profile based on a second digital activity and receiving a search result associated with the first digital activity;
 rescoring the first digital activity as malicious based on the search result; and 
 performing a security action associated with the rescored first digital activity. 
 
     
     
         2 . The method of  claim 1 , wherein the digital communication account is an email account associated with a collaboration suite. 
     
     
         3 . The method of  claim 1 , wherein the digital communication account is an account associated with a messaging platform. 
     
     
         4 . The method of  claim 1 , wherein the one or more attributes include at least one of: a source Internet Protocol (IP) address, a time of transmission, a geographical origin, a sender identity, a recipient identity, content, or presence of an attachment. 
     
     
         5 . The method of  claim 1 , wherein generating the searchable user communication digital profile comprises training a machine learning model based on past digital activities associated with the first user to establish normal behavior for the first user. 
     
     
         6 . The method of  claim 1 , wherein the searchable user communication digital profile includes records for digital activities initially scored as safe and digital activities initially scored as unsafe. 
     
     
         7 . The method of  claim 1 , wherein the second digital activity comprises a third digital activity performed using the digital communication account or another digital communication account associated with the first user or a second user. 
     
     
         8 . The method of  claim 1 , wherein rescoring the first digital activity as malicious is further based on input received from a security operations center (SOC) analyst interacting with an interface displaying the search result. 
     
     
         9 . The method of  claim 1 , wherein the security action comprises at least one of: quarantining the first digital activity, deleting the first digital activity, notifying an administrator, restricting access for the digital communication account, resetting a password for the digital communication account, or terminating active sessions for the digital communication account. 
     
     
         10 . The method of  claim 1 , wherein parsing data comprises obtaining the data via an Application Programming Interface (API) associated with the digital communication account. 
     
     
         11 . The method of  claim 1 , wherein the search result identifies the first digital activity based on sharing one or more attributes with the second digital activity. 
     
     
         12 . A system comprising:
 a processor configured to:
 parse data of a digital communication account of a first user for one or more attributes of a series of digital activities including a first digital activity initially scored as non-malicious; 
 based on the parsed data, generate a searchable user communication digital profile for the first user; 
 search the searchable user communication digital profile based on a second digital activity and receiving a search result associated with the first digital activity; 
 rescore the first digital activity as malicious based on the search result; and 
 perform a security action associated with the rescored first digital activity; and 
   a memory coupled to the processor and configured to provide the processor with instructions.   
     
     
         13 . The system of  claim 12 , wherein the digital communication account is an account associated with a messaging platform or a collaboration suite. 
     
     
         14 . The system of  claim 12 , wherein the one or more attributes include at least one of: a source Internet Protocol (IP) address, a time of transmission, a geographical origin, a sender identity, a recipient identity, content, or presence of an attachment. 
     
     
         15 . The system of  claim 12 , wherein generating the searchable user communication digital profile comprises training a machine learning model based on past digital activities associated with the first user to establish normal behavior for the first user. 
     
     
         16 . The system of  claim 12 , wherein the searchable user communication digital profile includes records for digital activities initially scored as safe and digital activities initially scored as unsafe. 
     
     
         17 . The system of  claim 12 , wherein the second digital activity comprises a third digital activity performed using the digital communication account or another digital communication account associated with the first user or a second user. 
     
     
         18 . The system of  claim 12 , wherein rescoring the first digital activity as malicious is further based on input received from a security operations center (SOC) analyst interacting with an interface displaying the search result. 
     
     
         19 . The system of  claim 12 , wherein the security action comprises at least one of: quarantining the first digital activity, deleting the first digital activity, notifying an administrator, restricting access for the digital communication account, resetting a password for the digital communication account, or terminating active sessions for the digital communication account. 
     
     
         20 . A computer program product, the computer program product being embodied in a non-transitory computer readable storage medium and comprising computer instructions for:
 parsing data of a digital communication account of a first user for one or more attributes of a series of digital activities including a first digital activity initially scored as non-malicious;   based on the parsed data, generating a searchable user communication digital profile for the first user;   searching the searchable user communication digital profile based on a second digital activity and receiving a search result associated with the first digital activity;   rescoring the first digital activity as malicious based on the search result; and   performing a security action associated with the rescored first digital activity.

Join the waitlist — get patent alerts

Track US2025254190A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.